On Wed, 13 Jul 2005, David McDowell wrote:
> What do you mean by sanity checking?
You don't want to readfile(/etc/hosts) or
readfile(some-internal-nda-document). Make sure the parameter is on a
list of permitted files before serving it out. A
readfile(spreadsheet-with-payroll-information) would be especially
bad, methinks...
--
John Berninger
GPG Key ID: A8C1D45C
Fingerprint: B1BB 90CB 5314 3113 CF22 66AE 822D 42A8 A8C1 D45C
Ita erat quando hic adveni.
--
--
TriLUG mailing list : http://www.trilug.org/mailman/listinfo/trilug
TriLUG Organizational FAQ : http://trilug.org/faq/
TriLUG Member Services FAQ : http://members.trilug.org/services_faq/
TriLUG PGP Keyring : http://trilug.org/~chrish/trilug.asc